-all or ~all: choosing your SPF policy
Hardfail rejects unlisted senders outright; softfail marks them and delivers anyway. Which you want depends on how complete your record already is.
The final mechanism in an SPF record decides what happens to everything the record did not explicitly authorise. There are four possible qualifiers and only two sensible choices.
The options
- -all (fail) means unlisted senders are not authorised. The strongest statement, and the one DMARC enforcement effectively expects.
- ~all (softfail) marks unlisted senders as suspicious but should still be accepted. Intended as a transition state.
- ?all (neutral) makes no assertion at all. Equivalent to publishing nothing, so do not use it.
- +all (pass) authorises the entire internet to send as you. Never correct.
How to choose
Publish ~all while you are still discovering who sends mail as your domain, then move to -all once DMARC aggregate reports show a stable, complete picture for several weeks. The move is a one-character edit, and it is the point at which SPF starts doing real work.
Under DMARC it is the alignment that carries the weight, not the qualifier: a DMARC policy of reject will act on an unaligned message whether your record ends in ~all or -all. The qualifier still matters for receivers checking SPF on its own.
The common trap
Teams often leave ~all in place for years because someone once got a bounce after tightening it. The right response is to find the sender that was missing from the record, not to weaken the policy permanently. DMARC reports tell you exactly which IPs are failing and how much mail they send.
More on SPF
What SPF actually does
SPF authorises servers, not messages, and it checks the envelope sender rather than the From address your recipient sees. That explains most SPF confusion.
Reading an SPF record, mechanism by mechanism
A walk through every mechanism and modifier you are likely to meet in a real SPF record.
The SPF ten-lookup limit, and how to stay under it
SPF evaluation is capped at ten DNS lookups. Exceed it and the result is permerror, which most receivers treat as a failure, including DMARC.